Challenge Board

Browse the full target list

Log in to reveal challenge IPs.

🐀🐀🐀🐀

🧩 LDAP Lab · 1 Machine

CorpNet

A two-machine Active Directory lab focused on pivoting. Only the domain controller (CORP-DC01) is internet-facing — the workstation lives deeper on the internal network. Enumerate the DC’s SMB shares, harvest credentials, then pivot inward to the domain-joined workstation (reachable at corp-ws.default.svc.cluster.local on standard ports 22/80/445, or straight from the in-browser Pwnbox) and chain the credential leaks to full domain compromise.

OSCP Active Directory
Entry Point Hidden until login
Progress 0 / 1 rooted
🐀🐀🐀🐀🐀

🧩 LDAP Lab · 2 Machines

MegaCorp

A two-machine Active Directory lab focused on MS14-025 (GPP credential harvest). Start with an exposed backup config on the workstation, then pivot to the domain controller via SYSVOL to decrypt the service account password and achieve root.

OSCP Active Directory
Entry Point Hidden until login
Progress 0 / 2 rooted
🐀🐀🐀🐀🐀

🧩 LDAP Lab · 1 Machine

VaultNet

A three-machine Active Directory lab focused on network pivoting. Only the domain controller is exposed to the internet. Players must chain SMB credential harvesting on the DC, SSH tunnelling, unrestricted file-upload RCE on the internal web server, and MySQL credential extraction on the internal database to fully compromise all three machines.

OSCP Active Directory Pivoting
Entry Point Hidden until login
Progress 0 / 1 rooted
🐀

🧩 LDAP Lab · 1 Machine

PurpleTeam

Five connected hosts. A company got compromised. You are the incident responder. Start here and follow the trail. --- Accessing the estate --- You're issued an incident-responder account: analyst / analyst123 (it works on every host). Only the CIRT gateway (cirt-gateway) is internet-facing — read its mission brief first. The other four hosts (siem-lab-pt, soar-lab, code-review-lab, active-defense-lab) live on the internal network. Reach them from your cirt-gateway shell, or from the in-browser Pwnbox, at <host>.default.svc.cluster.local (e.g. ssh analyst@siem-lab-pt.default.svc.cluster.local) on standard ports — or tunnel out (ssh -D / proxychains) and investigate from your own box. Work each host with your analyst account.

Web Network Enumeration Purple Team
Entry Point Hidden until login
Progress 0 / 1 rooted
🐀

🧩 LDAP Lab · 1 Machine

OperationSwitchboard

A telecom startup exposed its internal protocol stack. Navigate legacy daemons, misconfigured services, and credential leaks through five interconnected hosts. --- How to pivot --- Only the FTP gateway (sw-ftp) faces the internet — the other four hosts are reachable ONLY from inside the network. The play: pop sw-ftp first, then tunnel through it to reach the rest. 1. Land on sw-ftp. From that shell, the internal hosts answer on the cluster network at their service hostnames: sw-smtp, sw-redis, sw-rsync, sw-snmp (FQDN: <host>.default.svc.cluster.local) on STANDARD ports (SSH 22, SMTP 25, HTTP 80, Redis 6379, rsync 873, SNMP 161/udp) — not the public 30xxx ports. 2. Tunnel to scan/exploit them from your own box: SSH dynamic forward (ssh -D 1080 user@sw-ftp...) + proxychains, or per-service local forwards (ssh -L 6379:sw-redis:6379 user@sw-ftp...). Or just launch the in-browser Pwnbox — it sits inside the network and can hit them directly. 3. Each host has its OWN credentials — loot from one box won't log you into the next. Exploit each service to recover that host's creds. Reachability: sw-ftp -> sw-smtp / sw-redis / sw-rsync / sw-snmp. Work the chain.

Operation Switchboard Network File Shares Enumeration
Entry Point Hidden until login
Progress 0 / 1 rooted
🐀

🧩 LDAP Lab · 1 Machine

BlacksiteWebapp

Blacksite built five internal web tools in a hurry. Every tool has a classic OWASP Top 10 flaw. Move through the estate extracting credentials from each.

Blacksite Webapp Web Database
Entry Point Hidden until login
Progress 0 / 1 rooted
🐀

🧩 LDAP Lab · 1 Machine

PipelineBreach

A CI/CD pipeline exposed from dev to prod. Leaked commits, environment variables, registry credentials, and build server access form a chain from source to root.

Pipeline Breach DevOps Enumeration
Entry Point Hidden until login
Progress 0 / 1 rooted
🐀

🧩 LDAP Lab · 1 Machine

ExposedAPI

Five microservices shipped without a security review. BOLA, mass assignment, JWT forgery, broken function-level auth, and SSRF — the OWASP API Security Top 10 distilled into a single estate.

Exposed API Web Enumeration
Entry Point Hidden until login
Progress 0 / 1 rooted
🐀

🧩 LDAP Lab · 1 Machine

Cryptovault

Cryptovault rolled its own crypto. Five services expose predictable tokens, crackable JWT secrets, hash length extension, padding oracles, and a factorizable RSA key.

Cryptovault Web
Entry Point Hidden until login
Progress 0 / 1 rooted
🐀 🔒 Premium Only

🧩 LDAP Lab · 1 Machine

ContainmentFailure

Five containers with dangerous misconfigurations — capability abuse, proc filesystem leaks, writable host mounts, Docker socket escapes, and the cgroups notify_on_release technique.

Containment Failure DevOps Privesc
Progress 0 / 1 rooted
🐀 🔒 Premium Only

🧩 LDAP Lab · 1 Machine

MemoryLane

Five SUID binaries, five memory corruption vulnerabilities. ret2win, shellcode injection, ROP chains, format string exploitation, and heap corruption — built for binary exploitation beginners.

Memory Lane Binary Exploit Privesc
Progress 0 / 1 rooted
🐀

🧩 LDAP Lab · 1 Machine

SocialEngineeringSim

Technical OSINT on RatCorp infrastructure. Five services leak credentials through HTTP headers, robots.txt, document metadata, debug logs, and hidden API export endpoints.

Social Engineering Sim Web Enumeration
Entry Point Hidden until login
Progress 0 / 1 rooted
🐀🐀🐀

🧩 LDAP Lab · 3 Machines

CWAP Range

Nightglass is an anonymous customer support-ticket desk. Staff agents continuously review incoming tickets in an internal console — get your message in front of them and see what their session gives up. A CWAP Range machine focused on Blind / Stored XSS with an out-of-band callback.

CWAP Web
Entry Point Hidden until login
Progress 0 / 3 rooted
🐀🐀🐀

🧩 LDAP Lab · 3 Machines

Pentest Range

The Pentest Range is a set of realistic, deliberately-vulnerable business web apps built for full-engagement practice. There are NO flags to capture — each machine has multiple critical vulnerabilities. Your deliverable is the work a real pentester produces: a PTES-aligned test plan before you start, and a full report afterward. Reports are reviewed and graded for leaderboard points. Treat each box like a scoped client engagement: enumerate, exploit, assess impact, and document.

Pentest Practice Web
Entry Point Hidden until login
Progress 0 / 3 rooted
🐀🐀🐀🐀

🧩 LDAP Lab · 1 Machine

CWAP Exam

The CWAP Exam is a full, timed, AI-graded web-application engagement. RatSuite is a realistic SaaS app that hides the whole CWAP web-bug syllabus. There are NO flags — your deliverables ARE the exam: a PTES test plan before you start, a full professional report afterward, and a short spoken debrief video. All three are graded automatically by an AI examiner within minutes, against the same rubric a human assessor uses — an admin can review or adjust.

Entry Point Hidden until login
Progress 0 / 1 rooted
🐀🐀🐀

🧩 LDAP Lab · 1 Machine

Student Engagements

Student Engagements are authorized, scoped pentest assignments. You are handed a formal scope of work and treat the target exactly like a real client. There are NO flags — your deliverables are the professional artifacts (test plan, report, debrief video), reviewed and graded for the Student Program.

CWAP Web
Entry Point Hidden until login
Progress 0 / 1 rooted
🐀

Relay

Relay is a beginner-friendly pivot box: ten user accounts, ten flags, one flag per user. You are handed the first account — SSH in directly as relay01 with password R3lay_St4rt_01 (no exploit needed to land the first user), grab the flag, and find the clue each user leaves behind for the next. Walk the chain relay01 → relay02 → … → relay10. NOTE: there is NO root on this machine and no privilege-escalation path. The whole challenge is lateral movement between users — do not waste time hunting for root.

Pivoting Enumeration
IP Hidden until login
Progress - / -
🐀

Axferia

Axferia's nameserver has been running in the corner of the datacenter since before anyone on the team can remember. Nobody touches it. Nobody audits it. The sysadmin who set it up left years ago — and took the hardening checklist with him.

OSCP Network Enumeration
IP Hidden until login
Progress - / -
🐀

Listeria

Listeria started as a quick internal tool that was never meant to face the world. Then someone pointed a domain at it. A Friday afternoon deploy. No review. The developer responsible has since changed departments.

OSCP CPTS Web
IP Hidden until login
Progress - / -
🐀🐀

Bindforge

Every enterprise has a directory. Bindforge's directory holds the full map of who has access to what — accounts, groups, and a few fields that the original engineer populated a little too liberally. It was only ever meant to be accessed from inside the building.

OSCP CPTS Database Active Directory
IP Hidden until login
Progress - / -
🐀🐀

Rootbase

The Rootbase server has been the backbone of three different applications over five years. Each team that inherited it assumed the previous one had secured it properly. None of them checked.

OSCP Database
IP Hidden until login
Progress - / -
🐀🐀🐀🐀

Keyspace

Keyspace was provisioned as a temporary caching layer during a product launch. The launch went well. The cleanup never happened. The server is still running, still reachable, and nobody on the current team knows its password — or whether it has one.

OSCP Database
IP Hidden until login
Progress - / -
🐀🐀

Driftsync

Driftsync runs nightly, faithfully mirroring data from one machine to the next. The engineer who wrote the job configured it to be 'easy to use'. He was proud of how accessible he'd made it. That was two years ago.

OSCP Network File Shares
IP Hidden until login
Progress - / -
🐀🐀🐀

Bifrost

Bifrost was set up to bridge two legacy teams who couldn't agree on a file-sharing standard. So they ran both. Twice the surface, half the oversight. Somewhere in the middle of all that data lives a path forward.

OSCP CPTS Network File Shares
IP Hidden until login
Progress - / -
🐀🐀

Postmark

Postmark handles internal mail for a small ops team. It was stood up fast, kept running through three infrastructure migrations, and never got the security hardening that was always on next quarter's roadmap.

OSCP Network Enumeration
IP Hidden until login
Progress - / -
🐀🐀

Walkabout

Walkabout is the network monitoring node that nobody monitors. It has a view of every device on the segment — interface stats, process lists, everything the ops team ever thought to wire up. It reports faithfully to whoever asks.

OSCP Network Enumeration
IP Hidden until login
Progress - / -
🐀🐀🐀

Switchgear

Switchgear runs the office phone system — an Asterisk PBX humming along untouched since the last admin left. The extensions still register, the manager port still answers, and nobody ever changed the defaults from the install guide. 💡 Machine idea suggested by the community — thank you!

OSCP Network
IP Hidden until login
Progress - / -
🐀🐀🐀

DeployStation

The SwitchGear imaging server — an MDT deployment share that techs use to re-image workstations across the floor. It has been quietly handing out install images for years. Nobody ever checked who is allowed to read them. 💡 Community machine submitted by azureAD — thank you!

IP Hidden until login
Progress - / -
🐀🐀🐀🐀

Bastion

The jump host into SolarGate's contractor DMZ. Vendors get an account here — but not much of one. The shell you land in barely lets you breathe: no cd, no slashes, a handful of allowed commands. It was never meant to be a way in. Prove it is.

IP Hidden until login
Progress - / -
🐀🐀🐀🐀

Nightfall

The ops team built a 'hardened' network diagnostics tool so junior staff could run checks without touching root. They blocked the obvious injection tricks and called it done. They did not block all of them.

IP Hidden until login
Progress - / -
🐀🐀🐀

Sidewinder

One low-privilege service account and one forgotten config file — everything an operator needs to become someone more important, and then root. Foothold is the easy part. The move is the point.

IP Hidden until login
Progress - / -
🐀

Retrogate

Retrogate is the last machine in the building still running the old remote access service from the early 2000s. It survived every migration plan because removing it was always someone else's problem. The sysadmin who set it up retired. His habits did not.

OSCP Network
IP Hidden until login
Progress - / -
🐀

Bootleak

Bootleak's network boot server was set up to provision diskless clients in a lab that no longer exists. The server outlived the lab. It still serves. It still responds. It has no idea it shouldn't.

OSCP Network
IP Hidden until login
Progress - / -
🐀🐀🐀

Injectrix

The employee portal was built by a contractor in 2019, accepted without a security review, and has been quietly running ever since. It handles timesheets, leave requests, and a few internal tools nobody fully remembers adding. The codebase has never been audited.

OSCP CPTS Web
IP Hidden until login
Progress - / -
🐀🐀🐀🐀

Stacksmash

The binary on this machine is old. Older than most of the team. It was compiled once, deployed, and forgotten — a relic of infrastructure debt that nobody wanted to touch. It still runs as root. It always has.

OSCP Binary Exploit
IP Hidden until login
Progress - / -
🐀🐀🐀 🔒 Premium Only

RatHole

Deep beneath the city streets runs the RatHole — a forgotten server maintained by a rodent with more enthusiasm than operational discipline. The setup is scrappy, the maintenance is creative, and root has been running things down here for longer than anyone cares to admit.

Network Pivoting
Progress - / -
🐀🐀

Loophole

The document viewer was built over a long weekend to replace a tool that no longer worked. It went live on Monday. It has never been reviewed. The developer who built it is very proud of how quickly it shipped.

CPTS Web
IP Hidden until login
Progress - / -
🐀🐀🐀

Tempest

Tempest is an internal reporting tool that the development team is quietly proud of. It renders fast, it looks clean, and it was built without once consulting the documentation on safe input handling.

CPTS Web
IP Hidden until login
Progress - / -
🐀🐀

Docparse

DocuParse processes invoices for an accounts team that needed automation fast. The developer who built it enabled every feature the XML library offered, valued flexibility, and shipped the Friday before a long weekend.

CPTS Web
IP Hidden until login
Progress - / -
🐀🐀🐀

Jailkey

Jailkey is the authentication layer for a suite of internal tools. The team built it themselves rather than pulling in a dependency. They were thorough. They were careful. They just left one door open that they assumed nobody would find.

Web
IP Hidden until login
Progress - / -
🐀🐀🐀🐀

Debugtrap

Debugtrap is a Flask application running in an environment that was never quite finished. The developer tested locally, pushed to production, and moved on to the next feature. Somewhere between development and deployment, a setting that should have changed did not.

CPTS Web
IP Hidden until login
Progress - / -
🐀🐀🐀🐀🐀

DarkRat

r4tking built his own private operations platform — implant registry, remote probe, operator management. He thought it was locked down. Find the cracks, chain them together, and own the machine from web panel to root shell. Nothing here is accidental.

IP Hidden until login
Progress - / -
🐀🐀🐀🐀🐀 🔒 Premium Only

Mirage

MirrorNet Corp ran a covert data intelligence platform. After their takedown, one server was left running. The admin swore it was hardened — 'everything real is behind another layer'. Dozens of researchers have tried. They all came back with flags. Every one of them was fake.

Progress - / -
🐀🐀

Axiom

The SolarGate incident team flagged unusual activity on prod-web-01. A file-upload vulnerability gave an attacker a foothold as www-data, and the logs show things escalated from there. Your job: step into the analyst's seat, reconstruct what happened, and finish the job the attacker started.

IP Hidden until login
Progress - / -
🐀

Inkblot

Inkblot runs an internal CMS built by someone who trusted their logs a little too much. The file inclusion is right there. What you put in the request is what ends up in the log. What ends up in the log ends up on the page.

IP Hidden until login
Progress - / -
🐀🐀

Blindspot

Blindspot is an internal URL validation tool. It checks whether endpoints are reachable — and it makes those requests from the server. There's an internal configuration service that wasn't supposed to be externally accessible.

IP Hidden until login
Progress - / -
🐀🐀🐀

TokenSmith

TokenSmith is an internal OAuth 2.0 provider. It handles authorization flows and issues tokens to clients. There's a known issue in the tracker about redirect_uri validation — issue #214, filed months ago, still open.

IP Hidden until login
Progress - / -
🐀🐀🐀🐀 🔒 Premium Only

Threadbare

Threadbare runs a privileged file integrity checker. It verifies that you own a file before reading it as root. The check and the read are two separate operations — and the filesystem doesn't stand still between them.

Progress - / -
🐀🐀🐀

Breakout

Breakout is an internal container management console that was meant to be ops-only. Someone left a debug endpoint live. The container has more access to the runtime than it should — and so do you.

IP Hidden until login
Progress - / -
🐀🐀

Shapeshifter

Shapeshifter is an internal developer profile service built with Node.js. It lets users update their profile data through a flexible merge endpoint — one that trusts deeply nested JSON a little too much.

IP Hidden until login
Progress - / -
🐀🐀🐀 🔒 Premium Only

Synapse

Synapse is an internal ML Model Hub that lets data science teams upload and share serialized model files. The platform loads every uploaded model automatically — trusting the data because trust is faster than validation.

Progress - / -
🐀🐀🐀 🔒 Premium Only

NullSecurityX Lab

NullSecurityX runs an internal bug bounty triage platform. The dev team pushed source code to production with the .git directory intact. Three vulnerabilities to chain — none of them obvious until you look closely.

Web CPTS
Progress - / -
🐀

SolarGate

SolarGate Energy's solar monitoring server has a misconfigured Python binary and a web service that's a little too helpful. Foothold first, SUID second.

OSCP Privesc Web Project Meridian
IP Hidden until login
Progress - / -
🐀

Meridian Hub

The Meridian central data hub runs a root-owned cleanup task every minute. Someone on the ops team made the script world-writable. They trusted the filesystem more than they should have.

OSCP Privesc Network Project Meridian
IP Hidden until login
Progress - / -
🐀🐀

VoltCore

VoltCore's network diagnostics panel passes your input straight to ping. The sudo policy for the next hop is generous. Two steps to root.

OSCP Privesc Web Project Meridian
IP Hidden until login
Progress - / -
🐀🐀

GridLock

GridLock's power management node runs awk as root for log analysis. The IT team didn't read the GTFOBins entry for awk. You did.

OSCP Privesc Project Meridian
IP Hidden until login
Progress - / -
🐀🐀🐀

Apex

Apex is the hardest node in the SolarGate network. The document reader doesn't validate paths. Python has a capability it shouldn't. Chain them.

OSCP Privesc Web Project Meridian
IP Hidden until login
Progress - / -
🐀🐀🐀

Assembly Line

An ASP.NET Core profile-import microservice deserializes attacker-supplied JSON with Newtonsoft.Json TypeNameHandling.All — polymorphic $type metadata lets you instantiate arbitrary .NET types. One of the app's own types runs a shell command on a property set, giving unauthenticated RCE. Loot leaked SSH creds from config, then escalate via a sudo GTFObins one-liner.

IP Hidden until login
Progress - / -

No challenges match the selected filters.

Want to learn the methodology behind these labs? The XSS Rat's Endless Bundle includes 45+ courses, CNWPP/CAPIE/CxWAP certs, weekly live sessions, and all future releases — €300 one-time.
Get the Bundle

☠ Infection Chain

Find hidden fragment codes scattered across machines and unlock The Burrow — a secret area for those who dig deep.

Enter The Burrow →